Acceptable Use Policy

Last updated: 24 July 2026

This Acceptable Use Policy explains the permitted and prohibited use of the website, services, systems and technical support provided by SETUPROS LTD, trading as SetuprosTech.

It applies to customers, website visitors, authorised users and anyone using SetuprosTech services, accounts, platforms or technical resources.

Microsoft’s own service rules prohibit illegal, fraudulent, deceptive, harmful and security-circumvention activities. This policy follows the same general principles while applying them to SetuprosTech’s IT, Microsoft cloud, network and support services.

1. Company Information

Legal company name: SETUPROS LTD
Trading name: SetuprosTech
Company number: 17327322
Registered in: England and Wales
Registered office: 128 City Road, London, EC1V 2NX, United Kingdom
Website: setuprostech.com
Email: info@setuprostech.com

In this policy:

  • “SetuprosTech”, “we”, “us” and “our” mean SETUPROS LTD.
  • “Customer”, “you” and “your” mean any person or organisation using or requesting our services.
  • “Services” includes our website, IT support, Microsoft cloud assistance, remote access, network support, migration, configuration and related technology services.
  • “Systems” includes devices, accounts, networks, software, websites, cloud platforms and other technology environments.

2. Purpose of This Policy

This policy is designed to:

  • Protect customers, users and third parties;
  • Prevent unlawful or harmful activity;
  • Protect systems and information;
  • Support proper Microsoft and third-party service use;
  • Reduce security, fraud and abuse risks;
  • Define conduct that SetuprosTech will not support; and
  • Explain what may happen if this policy is breached.

Users should only access systems and data they are clearly authorised to use. UK guidance recognises unauthorised access and unauthorised acts affecting computer systems as offences under the Computer Misuse Act 1990.

3. General Acceptable Use

You may use SetuprosTech services only:

  • For lawful purposes;
  • Within the agreed service scope;
  • With appropriate ownership, permission or authority;
  • In compliance with applicable laws;
  • In accordance with software and subscription terms;
  • In a way that does not harm systems or other users;
  • In accordance with reasonable security instructions; and
  • In accordance with our other published policies and agreements.

You are responsible for the conduct of:

  • Your employees;
  • Contractors;
  • Administrators;
  • Authorised users;
  • Household members using supported personal devices; and
  • Anyone to whom you provide access credentials.

4. Authorised Access Only

You must not ask SetuprosTech to access, monitor, change, recover or control a device, account or system unless you are authorised to do so.

You must not:

  • Request access to another person’s email without permission;
  • Ask us to bypass a password or security control without lawful authority;
  • Request access to an employer-owned system without approval;
  • Provide stolen, leaked or improperly obtained credentials;
  • Misrepresent yourself as the account owner;
  • Request administrator access beyond your authority;
  • Ask us to recover information from a device you do not lawfully control; or
  • Use our services to obtain confidential information unlawfully.

SetuprosTech may require identity, ownership or authority confirmation before proceeding.

5. Prohibited Security Activity

You must not use our services to:

  • Gain unauthorised access to systems or data;
  • Bypass authentication or access controls;
  • Circumvent multi-factor authentication;
  • Disable security protections without authority;
  • Exploit software vulnerabilities unlawfully;
  • Scan, probe or test systems without permission;
  • Intercept communications;
  • Extract passwords, tokens or access keys;
  • Deploy keyloggers or credential-stealing tools;
  • Create hidden access accounts;
  • Install unauthorised remote-access software;
  • Evade security monitoring;
  • Conceal unauthorised activity; or
  • Interfere with another user’s access.

Security testing may only be supported where:

  • The customer owns or controls the relevant environment;
  • Written permission is available;
  • The scope is clearly defined;
  • Testing is lawful; and
  • SetuprosTech has expressly agreed to provide that service.

6. Malware and Harmful Software

You must not ask SetuprosTech to create, install, distribute, conceal or operate:

  • Viruses;
  • Ransomware;
  • Spyware;
  • Trojans;
  • Worms;
  • Botnets;
  • Credential-stealing software;
  • Destructive scripts;
  • Malicious macros;
  • Backdoors;
  • Cryptojacking software; or
  • Any other harmful code.

We may provide defensive services such as:

  • Malware removal;
  • Security assessment;
  • Device cleaning;
  • Recovery assistance;
  • Patch installation;
  • Security hardening; and
  • Incident-response guidance.

Defensive assistance does not include helping a customer create or improve malicious software.

7. Fraud, Impersonation and Deception

You must not use our services for:

  • Fraud;
  • Identity theft;
  • Impersonation;
  • False business representation;
  • Phishing;
  • Fake account creation;
  • Deceptive payment requests;
  • Manipulated invoices;
  • Misleading domain registrations;
  • False technical-support communications;
  • Credential harvesting;
  • Account takeover; or
  • Any attempt to mislead Microsoft, a supplier, bank, regulator or another third party.

Microsoft’s service rules similarly prohibit fraudulent, false, misleading and impersonating activity.

8. Email, Messaging and Spam

You must not use SetuprosTech services to:

  • Send unsolicited bulk messages;
  • Operate spam campaigns;
  • Send deceptive marketing;
  • Distribute phishing emails;
  • Hide the true sender;
  • Falsify message headers;
  • Use purchased or unlawfully obtained mailing lists;
  • Send malware or harmful links;
  • Evade unsubscribe requests;
  • Abuse Microsoft 365, Exchange Online or another provider’s sending limits; or
  • Damage the reputation of an email domain or service.

Customers remain responsible for ensuring that marketing communications comply with applicable privacy and electronic-marketing requirements.

9. Microsoft Accounts, Licences and Services

Where our services involve Microsoft products or platforms, you must:

  • Use genuine Microsoft licences;
  • Use subscriptions according to their assigned purpose;
  • Maintain the correct number of licences;
  • Follow Microsoft service and licence terms;
  • Use accurate account and organisation information;
  • Protect administrator accounts;
  • Avoid account sharing where prohibited;
  • Avoid false tenant or business registrations;
  • Avoid regional or identity misrepresentation;
  • Avoid unauthorised resale or redistribution; and
  • Follow any applicable Microsoft acceptable-use requirements.

You must not ask SetuprosTech to:

  • Supply counterfeit licence keys;
  • Activate unlawfully obtained software;
  • Circumvent product activation;
  • Share one licence across unauthorised users;
  • Misrepresent your location to obtain restricted services;
  • Create false Microsoft tenants;
  • Falsify partner, reseller or customer information; or
  • Bypass Microsoft security or service restrictions.

Microsoft may apply its own restrictions, suspension or enforcement measures independently of SetuprosTech.

10. Software Licensing and Copyright

You must not use our services to:

  • Install pirated software;
  • Use cracked applications;
  • Circumvent licence verification;
  • Copy software unlawfully;
  • Remove copyright or ownership notices;
  • Distribute protected material without permission;
  • Use unauthorised product keys;
  • Infringe software licence terms; or
  • Reproduce copyrighted content unlawfully.

You are responsible for ensuring that software, media, documents and data supplied to us may lawfully be used.

SetuprosTech may refuse to install or support software where the licence cannot reasonably be verified.

11. Data and Privacy

You must not use SetuprosTech services to:

  • Access personal data without authority;
  • Collect data unlawfully;
  • Monitor individuals secretly or unlawfully;
  • Export confidential information without permission;
  • Transfer personal information without an appropriate legal basis;
  • Retain information beyond your authority;
  • Circumvent privacy controls;
  • Conduct unlawful employee surveillance; or
  • Request disclosure of information you are not entitled to receive.

You must inform us where the requested service involves:

  • Sensitive personal information;
  • Regulated data;
  • Employee information;
  • Customer databases;
  • Health or financial information;
  • Children’s information; or
  • Other information requiring special protection.

We may require additional safeguards or a separate data-processing agreement.

12. Surveillance and Monitoring

SetuprosTech will not support unlawful surveillance.

You must not ask us to:

  • Secretly access another person’s camera or microphone;
  • Install spyware on another person’s device;
  • Track a person without lawful authority;
  • Read private messages without permission;
  • Monitor employees without appropriate notice or authority;
  • Record communications unlawfully;
  • Access location data without permission; or
  • Conceal monitoring software from an authorised device user.

Legitimate workplace security, parental controls or device-management services may only be supported where the customer has lawful authority and follows applicable notice and privacy requirements.

13. Harassment, Abuse and Harmful Conduct

You must not use our services to:

  • Harass;
  • Threaten;
  • Stalk;
  • Intimidate;
  • Bully;
  • Defame;
  • Discriminate unlawfully;
  • Promote violence;
  • Target vulnerable individuals;
  • Distribute abusive material; or
  • Facilitate harmful conduct.

You must not direct abusive, threatening or discriminatory conduct toward SetuprosTech employees, contractors or service providers.

Microsoft also prohibits conduct harmful to other users or its services.

14. Illegal or Restricted Content

You must not use our services to store, process, transmit or distribute content that:

  • Is illegal;
  • Infringes intellectual property;
  • Facilitates crime;
  • Promotes terrorism or violent extremism;
  • Contains unlawful sexual content;
  • Exploits children;
  • Encourages violence;
  • Contains unlawful hate material;
  • Is defamatory;
  • Violates privacy rights; or
  • Is otherwise prohibited by applicable law.

We may refuse assistance where a requested service would directly support prohibited content or conduct.

15. Network and Infrastructure Abuse

You must not use our services to:

  • Disrupt networks;
  • Flood systems with traffic;
  • Conduct denial-of-service attacks;
  • Interfere with network availability;
  • Consume unreasonable resources;
  • Operate unauthorised proxies or relays;
  • Hide malicious traffic;
  • Send spoofed network traffic;
  • Manipulate routing or DNS unlawfully;
  • Use compromised devices;
  • Evade network controls; or
  • Damage another organisation’s infrastructure.

Network security work must be conducted only within an authorised scope.

16. Cloud Resource Abuse

You must not use cloud services configured or supported by SetuprosTech for:

  • Malicious cryptocurrency mining;
  • Botnet operation;
  • Malware hosting;
  • Credential attacks;
  • Unauthorised scanning;
  • Mass scraping that violates applicable terms;
  • Spam delivery;
  • Fraudulent account creation;
  • Illegal file distribution;
  • Service disruption; or
  • Concealment of unlawful activity.

Customers are responsible for monitoring cloud resource usage and protecting administrative credentials.

17. Artificial Intelligence Services

Where a supported Microsoft or third-party service includes artificial intelligence features, you must not use it to:

  • Create unlawful content;
  • Facilitate fraud;
  • Impersonate individuals deceptively;
  • Generate malware;
  • Bypass security controls;
  • Produce harmful instructions;
  • Violate privacy rights;
  • Infringe intellectual property;
  • Manipulate systems unlawfully; or
  • Circumvent provider safeguards.

You remain responsible for reviewing AI-generated output before using it for business, legal, financial, technical or customer-facing purposes.

18. Resource and Service Misuse

You must not:

  • Use excessive system resources intentionally;
  • Interfere with service availability;
  • Abuse support channels;
  • Submit repeated false support requests;
  • Attempt to obtain services without payment;
  • Manipulate usage records;
  • Share support access with unauthorised parties;
  • Resell services without written permission;
  • Misuse evaluation or trial accounts;
  • Circumvent service limits; or
  • Exploit errors in pricing, access or configuration.

19. Account and Credential Security

You are responsible for:

  • Protecting passwords;
  • Using strong authentication;
  • Enabling multi-factor authentication where appropriate;
  • Restricting administrator access;
  • Removing former users;
  • Keeping contact information current;
  • Monitoring unusual activity;
  • Reporting suspected compromise promptly; and
  • Preventing unauthorised credential sharing.

The NCSC recommends making expected security behaviour clear to users and ensuring devices and accounts are used in ways that support organisational security.

SetuprosTech is not responsible for unauthorised activity caused by credentials that the customer failed to protect, subject to applicable law and our agreed responsibilities.

20. Customer Systems and Content

You remain responsible for:

  • Data stored in your systems;
  • Files provided to SetuprosTech;
  • Software installed at your request;
  • User-generated content;
  • Business communications;
  • Website content;
  • Email campaigns;
  • Account activity; and
  • The conduct of authorised users.

SetuprosTech does not routinely monitor customer content unless:

  • Monitoring forms part of an agreed security service;
  • Investigation is required following a reported incident;
  • It is necessary to provide support;
  • It is required by law; or
  • There is a reasonable indication of abuse.

21. Security Testing and Research

Requests involving penetration testing, vulnerability assessment or security research must be agreed separately.

The customer must provide:

  • Written authorisation;
  • Confirmed system ownership;
  • Defined targets;
  • Testing dates;
  • Permitted techniques;
  • Contact details;
  • Excluded systems;
  • Data-handling instructions; and
  • Emergency-stop procedures.

A general support request does not authorise security testing.

22. Reporting Security Concerns

Customers should promptly report:

  • Suspected account compromise;
  • Unrecognised administrator access;
  • Malware;
  • Data exposure;
  • Lost devices;
  • Phishing;
  • Unauthorised remote-access tools;
  • Suspicious payment requests;
  • Licence abuse; or
  • Other security concerns.

Reports should be sent to:

info@setuprostech.com

Use the subject:

Security Concern

Do not include passwords, authentication codes or unnecessary sensitive information in the initial email.

23. Investigation of Suspected Misuse

Where misuse is suspected, SetuprosTech may:

  • Request further information;
  • Verify account ownership;
  • Review relevant service records;
  • Review security or access logs;
  • Pause support work;
  • Restrict access;
  • Ask the customer to secure affected accounts;
  • Preserve evidence where legally appropriate;
  • Contact a relevant service provider; or
  • Report the matter where required by law.

Any investigation will be limited to what is reasonably necessary.

24. Suspension or Refusal of Service

We may refuse, restrict, suspend or terminate services where:

  • This policy is breached;
  • The requested activity appears unlawful;
  • Authority cannot be verified;
  • Fraud or impersonation is suspected;
  • Systems present an unreasonable security risk;
  • Payment has not been made;
  • A third-party provider requires suspension;
  • Continuing could harm another person or system;
  • The customer refuses reasonable security instructions; or
  • Continuing the service could expose SetuprosTech to legal or regulatory risk.

Where appropriate, we will explain the reason and provide an opportunity to correct the issue.

Immediate suspension may occur where there is a serious security, fraud or legal risk.

25. Removal of Content or Access

Where technically and legally appropriate, we may:

  • Disable a temporary account;
  • Revoke remote access;
  • Disconnect a support session;
  • Remove harmful files introduced through our service;
  • Block abusive traffic;
  • Suspend a managed service;
  • Decline to process unlawful content; or
  • Ask a third-party provider to investigate.

We will not remove customer-owned content without authority unless required by law, urgently necessary to address a security threat or permitted under an applicable agreement.

26. Third-Party Enforcement

Microsoft, hosting providers, registrars, cloud platforms and other suppliers may apply their own acceptable-use and enforcement rules.

A third-party provider may independently:

  • Restrict an account;
  • Block traffic;
  • Suspend a service;
  • Remove content;
  • Require identity verification;
  • Disable a licence;
  • Investigate misuse; or
  • Terminate access.

SetuprosTech cannot guarantee reversal of a third-party enforcement decision.

27. Costs Caused by Misuse

Subject to applicable law and the relevant agreement, the customer may be responsible for reasonable costs caused by misuse, including:

  • Security investigation;
  • Emergency remediation;
  • Recovery work;
  • Third-party charges;
  • Excessive cloud usage;
  • Malware cleanup;
  • Account restoration;
  • Data recovery;
  • Legal or professional advice; and
  • Additional support time.

We will not apply excessive or punitive charges.

28. Cooperation with Authorities

SetuprosTech may preserve or disclose relevant information where:

  • Required by law;
  • Required by a valid court order;
  • Requested by an authorised regulator;
  • Necessary to protect legal rights;
  • Necessary to respond to an immediate threat; or
  • Permitted under applicable data-protection law.

We will not voluntarily disclose customer information beyond what is reasonably necessary and lawful.

29. No Waiver of Legal Rights

Nothing in this policy:

  • Authorises unlawful activity;
  • Limits mandatory consumer rights;
  • Removes SetuprosTech’s legal obligations;
  • Prevents lawful security research under an expressly agreed scope; or
  • Prevents a customer from reporting concerns to an appropriate authority.

30. Relationship with Other Policies

This policy should be read together with:

  • Privacy Policy;
  • Cookie Policy;
  • Terms of Service;
  • Service Cancellation and Refund Policy;
  • Remote Support and Access Policy; and
  • Any accepted quotation, service agreement or scope of work.

Where a specific written agreement includes stricter security or acceptable-use requirements, those specific requirements will also apply.

31. Changes to This Policy

We may update this policy to reflect:

  • Changes to our services;
  • New security risks;
  • Changes to Microsoft or supplier requirements;
  • Legal or regulatory changes;
  • Changes to our systems; or
  • Changes to our operating procedures.

The latest version will be published with an updated revision date.

32. Contact Us

Questions about acceptable use or suspected misuse should be sent to:

SETUPROS LTD, trading as SetuprosTech
Email: info@setuprostech.com
Registered office: 128 City Road, London, EC1V 2NX, United Kingdom
Company number: 17327322
Registered in: England and Wales